ZAP Scanning Report
ZAP Scanning Report
Contents
About this report
Report parameters
Summaries
Alerts
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 1/11
11/26/22, 4:30 PM ZAP Scanning Report
Appendix
Alert types
Contexts
Sites
http://www.hipertexto.info
An included site must also be within one of the included contexts for its
data to be included in the report.
Risk levels
Included:
High, Medium, Low, Informational
Excluded:
None
Confidence levels
Included:
User Confirmed, High, Medium, Low
Excluded:
User Confirmed, High, Medium, Low, False Positive
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 2/11
11/26/22, 4:30 PM ZAP Scanning Report
Summaries
Alert counts by risk and confidence
This table shows the number of alerts for each level of risk and confidence
included in the report.
Confidence
User
Confirmed High Medium Low Total
High 0
1
0
0
1
Medium 0
1
1
1
3
Low 0
0
2
1
3
Informationa 0
0
1
1
2
Total 0
2
4
3
9
This table shows, for each site for which one or more alerts were raised, the
number of alerts raised at each risk level.
Alerts with a confidence level of "False Positive" have been excluded from these
counts.
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 3/11
11/26/22, 4:30 PM ZAP Scanning Report
(The numbers in brackets are the number of alerts raised for the site at or above
that risk level.)
Risk
Information
al
High
Medium
Low
(>= Informa
(= High) (>= Medium) (>= Low) tional)
http://www.hipertext 1
3
3
2
This table shows the number of alerts of each alert type, together with the alert
type's risk level.
(33.3%)
(33.3%)
Set (4,811.1%)
(2,022.2%)
Total 9
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 4/11
11/26/22, 4:30 PM ZAP Scanning Report
(22.2%)
(20,622.2%)
Comments (11.1%)
(1,955.6%)
Total 9
Alerts
Risk=High, Confidence=High (1)
http://www.hipertexto.info (1)
GET http://www.hipertexto.info/desglobaliza/globalizacion.pdf
http://www.hipertexto.info (1)
GET http://www.hipertexto.info/documentos/internet_tegn.htm
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 5/11
11/26/22, 4:30 PM ZAP Scanning Report
http://www.hipertexto.info (1)
GET http://www.hipertexto.info/documentos/internet_tegn.htm
http://www.hipertexto.info (1)
GET http://www.hipertexto.info/Buscador/buscador.htm
http://www.hipertexto.info (2)
GET http://www.hipertexto.info/documentos/internet_tegn.htm
GET http://www.hipertexto.info/documentos/internet_tegn.htm
http://www.hipertexto.info (1)
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 6/11
11/26/22, 4:30 PM ZAP Scanning Report
GET http://www.hipertexto.info/documentos/localiz.htm
http://www.hipertexto.info (1)
GET http://www.hipertexto.info/documentos/internet_tegn.htm
http://www.hipertexto.info (1)
GET http://www.hipertexto.info/Buscador/buscador.htm
Appendix
Alert types
This section contains additional information on the types of alerts in the report.
PII Disclosure
CWE ID 359
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 7/11
11/26/22, 4:30 PM ZAP Scanning Report
WASC ID 13
CWE ID 352
WASC ID 9
Reference http://projects.webappsec.org/Cross-Site-
Request-Forgery
http://cwe.mitre.org/data/definitions/352.html
CWE ID 693
WASC ID 15
Reference https://developer.mozilla.org/en-
US/docs/Web/Security/CSP/Introducing_Content
_Security_Policy
https://cheatsheetseries.owasp.org/cheatsheets/
Content_Security_Policy_Cheat_Sheet.html
http://www.w3.org/TR/CSP/
http://w3c.github.io/webappsec/specs/content-
security-policy/csp-specification.dev.html
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 8/11
11/26/22, 4:30 PM ZAP Scanning Report
http://www.html5rocks.com/en/tutorials/security
/content-security-policy/
http://caniuse.com/#feat=contentsecuritypolicy
http://content-security-policy.com/
CWE ID 1021
WASC ID 15
Reference https://developer.mozilla.org/en-
US/docs/Web/HTTP/Headers/X-Frame-Options
CWE ID 200
WASC ID 13
Reference
http://blogs.msdn.com/b/varunm/archive/2013/0
4/23/remove-unwanted-http-response-
headers.aspx
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 9/11
11/26/22, 4:30 PM ZAP Scanning Report
http://www.troyhunt.com/2012/02/shhh-dont-
let-your-response-headers.html
CWE ID 200
WASC ID 13
Reference
http://projects.webappsec.org/w/page/13246936
/Information%20Leakage
CWE ID 693
WASC ID 15
Reference http://msdn.microsoft.com/en-
us/library/ie/gg622941%28v=vs.85%29.aspx
https://owasp.org/www-
community/Security_Headers
CWE ID 200
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 10/11
11/26/22, 4:30 PM ZAP Scanning Report
WASC ID 13
file:///C:/Users/erojas/2022-11-26-ZAP-Report-.html#alert-type-1 11/11